Bahagyang Totoo

Rating: 6.5/10

Coalition
C0298

Ang Claim

“Rolled out the My Health Record to the whole country as an opt-out system, despite safety concerns about how abusive stalkers can use it, and despite the trial involving 9 security breaches. 42 more security breaches happened within weeks of the system being rolled out nationally.”
Orihinal na Pinagmulan: Matthew Davis

Orihinal na Pinagmulan

FACTUAL NA BERIPIKASYON

### Trial Phase and Initial Breaches
### Trial Phase and Initial Breaches
The trial phase of My Health Record ran from January 2016 in Far North Queensland and NSW Nepean Blue Mountains, involving approximately 1 million participants [1].
The trial phase of My Health Record ran from January 2016 in Far North Queensland and NSW Nepean Blue Mountains, involving approximately 1 million participants [1].
The claim references "9 security breaches" during the trial.
The claim references "9 security breaches" during the trial.
According to available records, there were **35 breach notifications reported during the 2016-17 period**, which covered both the trial phase and the early rollout implementation [2].
According to available records, there were **35 breach notifications reported during the 2016-17 period**, which covered both the trial phase and the early rollout implementation [2].
The specific figure of "9" does not match documented records, though the existence of security breaches during this period is confirmed.
The specific figure of "9" does not match documented records, though the existence of security breaches during this period is confirmed.
### The 42 Breaches Claim
### The 42 Breaches Claim
The claim that "42 more security breaches happened within weeks of the system being rolled out nationally" is partially accurate but significantly misleading in its timeframe.
The claim that "42 more security breaches happened within weeks of the system being rolled out nationally" is partially accurate but significantly misleading in its timeframe.
The Australian Digital Health Agency (ADHA) reported 42 data breaches between July 1, 2017, and June 30, 2018 [2].
The Australian Digital Health Agency (ADHA) reported 42 data breaches between July 1, 2017, and June 30, 2018 [2].
However, this 12-month period does not represent "within weeks" of the October 15, 2018 national rollout to opt-out; rather, many of these breaches occurred before the system-wide changeover.
However, this 12-month period does not represent "within weeks" of the October 15, 2018 national rollout to opt-out; rather, many of these breaches occurred before the system-wide changeover.
The rollout commenced gradually, and the 12-month timeframe covers a broader period than suggested by the claim [3].
The rollout commenced gradually, and the 12-month timeframe covers a broader period than suggested by the claim [3].
### Nature of Reported Breaches
### Nature of Reported Breaches
Critically, the ADHA explicitly stated **"There have been no purposeful or malicious attacks compromising the integrity or security of the My Health Record system"** [2].
Critically, the ADHA explicitly stated **"There have been no purposeful or malicious attacks compromising the integrity or security of the My Health Record system"** [2].
Of the 42 reported breaches during this period: - 17 involved intertwined records (two or more people using the same Medicare record) - 22 involved attempted Medicare fraud (unauthorized claims appearing in records) - 3 were reported to the Office of the Australian Information Commissioner (OAIC) [2] These were primarily administrative and fraud-related issues rather than security breaches in the traditional sense (unauthorized system access, data exfiltration, etc.).
Of the 42 reported breaches during this period: - 17 involved intertwined records (two or more people using the same Medicare record) - 22 involved attempted Medicare fraud (unauthorized claims appearing in records) - 3 were reported to the Office of the Australian Information Commissioner (OAIC) [2] These were primarily administrative and fraud-related issues rather than security breaches in the traditional sense (unauthorized system access, data exfiltration, etc.).
### Opt-Out System Implementation
### Opt-Out System Implementation
The claim accurately states that the system was converted to opt-out rather than opt-in.
The claim accurately states that the system was converted to opt-out rather than opt-in.
The Coalition government changed the My Health Record from an opt-in model (inherited from Labor's original Personal Controlled Electronic Health Record system) to opt-out on October 15, 2018 [4].
The Coalition government changed the My Health Record from an opt-in model (inherited from Labor's original Personal Controlled Electronic Health Record system) to opt-out on October 15, 2018 [4].
By September 2018, approximately 900,000 Australians had already opted out of the system [4].
By September 2018, approximately 900,000 Australians had already opted out of the system [4].
### Domestic Violence and Stalker Safety Concerns
### Domestic Violence and Stalker Safety Concerns
The claim's reference to "safety concerns about how abusive stalkers can use it" is a legitimate and well-documented concern.
The claim's reference to "safety concerns about how abusive stalkers can use it" is a legitimate and well-documented concern.
Clinical documents in My Health Record may contain healthcare provider addresses and location information that could be misused by domestic violence perpetrators [5].
Clinical documents in My Health Record may contain healthcare provider addresses and location information that could be misused by domestic violence perpetrators [5].
Several safeguards were officially implemented: - Restriction codes to limit record access - Option to register with a pseudonym - Medicare upload control settings However, privacy advocates raised concerns that these protections were not universally understood or consistently applied [5].
Several safeguards were officially implemented: - Restriction codes to limit record access - Option to register with a pseudonym - Medicare upload control settings However, privacy advocates raised concerns that these protections were not universally understood or consistently applied [5].
The concern that inadequate privacy protections could deter domestic violence survivors from seeking medical care is documented in privacy impact assessments [5].
The concern that inadequate privacy protections could deter domestic violence survivors from seeking medical care is documented in privacy impact assessments [5].

Nawawalang Konteksto

The claim omits several important contextual elements: 1. **Labor Created the Original System**: The My Health Record system was originally developed by the Labor government as the "Personal Controlled Electronic Health Record" (PCEHR), launched July 1, 2012, with approximately $467 million invested [6].
The claim omits several important contextual elements: 1. **Labor Created the Original System**: The My Health Record system was originally developed by the Labor government as the "Personal Controlled Electronic Health Record" (PCEHR), launched July 1, 2012, with approximately $467 million invested [6].
The Coalition's contribution was rebranding it and changing from opt-in to opt-out, not creating a new system from scratch. 2. **Lack of Malicious Attacks**: The claim implies serious security vulnerabilities, but ADHA's explicit statement that there were "no purposeful or malicious attacks" indicates the reported breaches were administrative rather than security failures in the technical sense [2]. 3. **Timeline Misrepresentation**: The 42 breaches occurred over a 12-month period (July 2017-June 2018), not "within weeks" of the October 2018 national rollout.
The Coalition's contribution was rebranding it and changing from opt-in to opt-out, not creating a new system from scratch. 2. **Lack of Malicious Attacks**: The claim implies serious security vulnerabilities, but ADHA's explicit statement that there were "no purposeful or malicious attacks" indicates the reported breaches were administrative rather than security failures in the technical sense [2]. 3. **Timeline Misrepresentation**: The 42 breaches occurred over a 12-month period (July 2017-June 2018), not "within weeks" of the October 2018 national rollout.
This significantly misrepresents the severity and immediacy of the problem. 4. **Parliamentary Response**: Following safety concerns raised during the 2018 rollout, the Coalition government introduced the My Health Records Amendment (Strengthening Privacy) Bill 2018 (August 22, 2018) to prevent unauthorized government and law enforcement access without court order, demonstrating some responsiveness to privacy concerns [7].
This significantly misrepresents the severity and immediacy of the problem. 4. **Parliamentary Response**: Following safety concerns raised during the 2018 rollout, the Coalition government introduced the My Health Records Amendment (Strengthening Privacy) Bill 2018 (August 22, 2018) to prevent unauthorized government and law enforcement access without court order, demonstrating some responsiveness to privacy concerns [7].

Pagsusuri ng Kredibilidad ng Pinagmulan

The original sources provided include News Mail (regional Australian news outlet) and Daily Mail UK (tabloid publication).
The original sources provided include News Mail (regional Australian news outlet) and Daily Mail UK (tabloid publication).
Daily Mail is a mass-market tabloid known for sensationalism and has a history of both factual reporting and exaggeration depending on the story [8].
Daily Mail is a mass-market tabloid known for sensationalism and has a history of both factual reporting and exaggeration depending on the story [8].
News Mail is a regional Queensland publication with less well-established national reputation for investigative journalism.
News Mail is a regional Queensland publication with less well-established national reputation for investigative journalism.
Neither source is an authoritative primary source (government agency, parliamentary records, or independent audit).
Neither source is an authoritative primary source (government agency, parliamentary records, or independent audit).
The claim's phrasing ("despite the trial involving 9 security breaches...42 more...within weeks") uses alarmist language and implies a security crisis that ADHA's official statements do not support.
The claim's phrasing ("despite the trial involving 9 security breaches...42 more...within weeks") uses alarmist language and implies a security crisis that ADHA's official statements do not support.
This framing suggests the original sources may have prioritized attention-grabbing headlines over precise representation of breach types and timelines.
This framing suggests the original sources may have prioritized attention-grabbing headlines over precise representation of breach types and timelines.
⚖️

Paghahambing sa Labor

**Did Labor create or propose a similar health records system?** Yes, the Labor government created the original personal health records system.
**Did Labor create or propose a similar health records system?** Yes, the Labor government created the original personal health records system.
The Personal Controlled Electronic Health Record (PCEHR) was launched by the Rudd-Gillard Labor government on July 1, 2012, with $467 million in investment [6].
The Personal Controlled Electronic Health Record (PCEHR) was launched by the Rudd-Gillard Labor government on July 1, 2012, with $467 million in investment [6].
The key difference in approach was model design: Labor's PCEHR was opt-in (voluntary), meaning individuals had to actively register to have a record created [6].
The key difference in approach was model design: Labor's PCEHR was opt-in (voluntary), meaning individuals had to actively register to have a record created [6].
The Coalition government inherited this system and rebranded it as "My Health Record" while changing it to opt-out in October 2018 [4]. **Comparison of approach**: The systemic concern about privacy and security is not unique to the Coalition—both parties had to grapple with managing millions of health records in a digital system.
The Coalition government inherited this system and rebranded it as "My Health Record" while changing it to opt-out in October 2018 [4]. **Comparison of approach**: The systemic concern about privacy and security is not unique to the Coalition—both parties had to grapple with managing millions of health records in a digital system.
Labor's opt-in model meant fewer people were enrolled, which may have reduced exposure to privacy risks but also meant lower health system integration.
Labor's opt-in model meant fewer people were enrolled, which may have reduced exposure to privacy risks but also meant lower health system integration.
The Coalition's opt-out model prioritized health system efficiency and integration but increased privacy exposure for all Australians regardless of individual preference [4].
The Coalition's opt-out model prioritized health system efficiency and integration but increased privacy exposure for all Australians regardless of individual preference [4].
🌐

Balanseng Pananaw

**Coalition's Justification**: The shift to opt-out was framed as improving healthcare outcomes by ensuring more comprehensive health data integration and accessibility for treating clinicians.
**Coalition's Justification**: The shift to opt-out was framed as improving healthcare outcomes by ensuring more comprehensive health data integration and accessibility for treating clinicians.
An opt-out system with 900,000+ initial opt-outs still achieved broad population coverage while allowing those with privacy concerns to withdraw [4]. **Legitimate Privacy Concerns**: The safety risks for domestic violence survivors and abuse victims are real and documented.
An opt-out system with 900,000+ initial opt-outs still achieved broad population coverage while allowing those with privacy concerns to withdraw [4]. **Legitimate Privacy Concerns**: The safety risks for domestic violence survivors and abuse victims are real and documented.
The existence of provider location information in clinical notes creates genuine privacy risks for people fleeing abusive situations [5].
The existence of provider location information in clinical notes creates genuine privacy risks for people fleeing abusive situations [5].
These concerns were raised by victim support organizations and privacy advocates during the rollout period. **Nature of the Breaches**: While 42 breaches sound alarming, ADHA's classification and statement that no malicious attacks occurred suggests these were operational issues (wrong record access, fraud attempts flagged by the system itself) rather than security infrastructure failures or data theft [2].
These concerns were raised by victim support organizations and privacy advocates during the rollout period. **Nature of the Breaches**: While 42 breaches sound alarming, ADHA's classification and statement that no malicious attacks occurred suggests these were operational issues (wrong record access, fraud attempts flagged by the system itself) rather than security infrastructure failures or data theft [2].
This is an important distinction—the system flagged problems rather than failing to detect them. **Process and Response**: The Coalition government did respond to privacy concerns raised during the rollout by introducing amendments to prevent government and law enforcement access without court order, showing some responsiveness to legitimate concerns [7].
This is an important distinction—the system flagged problems rather than failing to detect them. **Process and Response**: The Coalition government did respond to privacy concerns raised during the rollout by introducing amendments to prevent government and law enforcement access without court order, showing some responsiveness to legitimate concerns [7].
However, critics argue the initial rollout was rushed and safety concerns were not adequately addressed before implementation. **Key context**: While the Coalition changed the system from opt-in to opt-out, the foundational architecture and many of the security challenges were inherited from Labor's original design.
However, critics argue the initial rollout was rushed and safety concerns were not adequately addressed before implementation. **Key context**: While the Coalition changed the system from opt-in to opt-out, the foundational architecture and many of the security challenges were inherited from Labor's original design.
The real policy debate is about whether opt-in versus opt-out better serves both healthcare outcomes and privacy protection—a legitimate disagreement between parties rather than a unique Coalition failure.
The real policy debate is about whether opt-in versus opt-out better serves both healthcare outcomes and privacy protection—a legitimate disagreement between parties rather than a unique Coalition failure.

BAHAGYANG TOTOO

6.5

sa 10

The claim contains accurate elements (security breaches did occur, opt-out system was implemented, domestic violence safety concerns are real) but significantly misrepresents the nature and severity of the security issues and the timeframe of breaches.
The claim contains accurate elements (security breaches did occur, opt-out system was implemented, domestic violence safety concerns are real) but significantly misrepresents the nature and severity of the security issues and the timeframe of breaches.
The "9 breaches during trial" figure does not match documented records (35 reported in 2016-17), and the "42 breaches within weeks of rollout" misrepresents a 12-month period and downplays ADHA's explicit statement that no malicious attacks occurred.
The "9 breaches during trial" figure does not match documented records (35 reported in 2016-17), and the "42 breaches within weeks of rollout" misrepresents a 12-month period and downplays ADHA's explicit statement that no malicious attacks occurred.
The framing creates an impression of a severe security crisis rather than an operational health system grappling with privacy and administrative challenges.
The framing creates an impression of a severe security crisis rather than an operational health system grappling with privacy and administrative challenges.

📚 MGA PINAGMULAN AT SANGGUNIAN (8)

  1. 1
    digitalhealth.gov.au

    digitalhealth.gov.au

    Digitalhealth Gov

  2. 2
    digitalhealth.gov.au

    digitalhealth.gov.au

    Digitalhealth Gov

  3. 3
    cyware.com

    cyware.com

    Cyware

    Original link unavailable — view archived version
  4. 4
    spectrum.ieee.org

    spectrum.ieee.org

    A wave of opt-outs highlights distrust in the government’s security and privacy promises

    IEEE Spectrum
  5. 5
    privacy.org.au

    privacy.org.au

    Privacy Org
  6. 6
    digitalhealth.gov.au

    digitalhealth.gov.au

    Digitalhealth Gov

  7. 7
    parlinfo.aph.gov.au

    parlinfo.aph.gov.au

    Parlinfo Aph Gov

  8. 8
    ipso.co.uk

    ipso.co.uk

    IPSO - the Independent Press Standards Organisation - is the independent regulator for the UK digital and print news industry.

    IPSO

Pamamaraan ng Rating Scale

1-3: MALI

Hindi tama sa katotohanan o malisyosong gawa-gawa.

4-6: BAHAGYA

May katotohanan ngunit kulang o baluktot ang konteksto.

7-9: HALOS TOTOO

Maliit na teknikal na detalye o isyu sa pagkakasulat.

10: TUMPAK

Perpektong na-verify at patas ayon sa konteksto.

Pamamaraan: Ang mga rating ay tinutukoy sa pamamagitan ng cross-referencing ng opisyal na mga rekord ng pamahalaan, independiyenteng mga organisasyong nag-fact-check, at mga primaryang dokumento.